Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
105 results
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicsinformation-gathering+5
11.0k
11 months ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1622 years ago
DarkAgent preview

DarkAgent

GitHubilikenwf/darkagent

DarkAgent Remote Administration Tool RAT by DragonHunter

command-and-controlpenetration-testingpost-exploitation+3
14213 years ago
NullGate preview

NullGate

GitHub0xsch1zo/nullgate

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

adversarial-attackencryption-decryption-toolspayload-development+3
1681 year ago
Seatbelt preview

Seatbelt

GitHubghostpack/seatbelt

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

defensive-toolsinformation-gatheringpenetration-testing+5
4.7k1 year ago
PixelCode-Attack preview

PixelCode-Attack

GitHubs3n4t0r-0x0/pixelcode-attack

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

command-and-controldata-exfiltrationeducation+8
1716 months ago
SharpWeb preview

SharpWeb

GitHubdjhohnstein/sharpweb

.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.

information-gatheringpassword-crackingpost-exploitation+1
5408 years ago
Why-so-Serious-SAM preview

Why-so-Serious-SAM

GitHubp1rat3r00t/why-so-serious-sam

PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

ctfeducationexploitation+6
1 year ago
EvilSelenium preview

EvilSelenium

GitHubmrd0x/evilselenium

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

data-exfiltrationinformation-gatheringphishing-tools+3
6054 years ago
MalvexC2 preview

MalvexC2

GitHuberarnitox/malvexc2

A simple C2 Framework written in modern C++

command-and-controleducationexploit-frameworks+6
321 month ago
Malicious-MCP preview

Malicious-MCP

GitHubquinnbast/malicious-mcp

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

ai-securitycommand-and-controldata-exfiltration+8
84 months ago
Tokenizer preview
Archived

Tokenizer

GitHubzeromemoryex/tokenizer

Kernel Mode Driver for Elevating Process Privileges

exploitationpost-exploitationprivilege-escalation+1
1293 years ago
ZeroLogon-PoC-DC-Pwn preview

ZeroLogon-PoC-DC-Pwn

GitHubmods20hh/zerologon-poc-dc-pwn

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

educationexploitationpapers-research+6
46 days ago
MemFiles preview

MemFiles

GitHuboctoberfest7/memfiles

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

command-and-controldata-exfiltrationpost-exploitation+1
4772 years ago
SharpNamedPipePTH preview

SharpNamedPipePTH

GitHubs3cur3th1ssh1t/sharpnamedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+5
3104 years ago
Lime-RAT preview
Archived

Lime-RAT

GitHubnyan-x-cat/lime-rat

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

command-and-controlcryptographydata-exfiltration+7
1.1k7 years ago
BeRoot preview

BeRoot

GitHubalessandroz/beroot

Privilege Escalation Project - Windows / Linux / Mac

misconfigurationpenetration-testingpost-exploitation+1
2.6k1 year ago
TeamsImplant preview

TeamsImplant

GitHuballevon412/teamsimplant
command-and-controlexploit-frameworkspayload-development+5
2084 years ago
Previous123456Next